Impact
The vulnerability arises from a hard‑coded constant used for JWT verification when the environment variable that would normally supply a secret is missing. This flaw allows unauthenticated actors to craft JWTs with any tenant identifier they choose, effectively bypassing normal authentication checks. The result is that attackers can subscribe to real‑time WebSocket and SSE endpoints for other tenants, retrieving sensitive information such as live alerts, cases, agent events, and graph updates that belong to those tenants.
Affected Systems
Beenuar’s AiSOC product versions from 7.5.0 up to but excluding 12.0.0 are affected. In these releases, the realtime WebSocket and SSE services do not enforce proper JWT verification unless the AISOC_REALTIME_JWT_SECRET environment variable is configured. Version 12.0.0 introduces a change that requires the secret to be set, thereby mitigating the issue.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, though the EPSS score is not available, implying that historical data on exploitation frequency is lacking. The vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit this flaw remotely via the realtime endpoints, forging subscription tickets by using a known or guessed hard‑coded secret. Since no advanced permissions are required, the risk of cross‑tenant data exposure is significant there is no additional protection in place.
OpenCVE Enrichment